OpenEMR is a free and open source electronic health records and medical practice management application. From 5.0.2 to before 8.0.0, there are (at least) two paths where the gateway_api_key secret value is rendered to the client in plaintext. These secret keys being leaked could result in arbitrary money movement or broad account takeover of payment gateway APIs. This vulnerability is fixed in 8.0.0.
Metrics
Affected Vendors & Products
References
History
Tue, 03 Mar 2026 22:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | OpenEMR is a free and open source electronic health records and medical practice management application. From 5.0.2 to before 8.0.0, there are (at least) two paths where the gateway_api_key secret value is rendered to the client in plaintext. These secret keys being leaked could result in arbitrary money movement or broad account takeover of payment gateway APIs. This vulnerability is fixed in 8.0.0. | |
| Title | OpenEMR's payments gateway_api_key secret rendered into client JS code | |
| Weaknesses | CWE-200 | |
| References |
|
|
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2026-03-03T22:08:22.564Z
Reserved: 2026-01-29T15:39:11.821Z
Link: CVE-2026-25146
No data.
Status : Received
Published: 2026-03-03T22:16:28.603
Modified: 2026-03-03T22:16:28.603
Link: CVE-2026-25146
No data.
OpenCVE Enrichment
No data.